decisionhealth Newsletters, Answer Books - 2006 Issue 3 (March)
Program_Memos / 2001 / AB-01-49
Subscribe or sign in to view the full article.
Article Overview
This article explains HCFA guidance for Medicare contractors on completing a security self-assessment and preparing a system security plan architecture. It is relevant to organizations handling Medicare data, especially security, systems, and compliance staff responsible for planning, documentation, and submission of contractor security materials. The article covers security review areas, worksheet-based planning, system inventory, reporting, and references to related HCFA materials.
Why This Topic Matters
It helps Medicare contractors understand the scope of HCFA’s 2001 security documentation expectations and the types of operational, technical, and administrative information needed for submission.
Article Sections
-
Security Questions and Concerns
Contact and support information for questions about the memorandum, related security requirements, and the submission process.
-
Self-Assessment Process
An overview of the recommended process for performing the HCFA security self-assessment, including planning, personnel involvement, review, documentation, and submission steps.
-
Introduction
Background on system security plan architecture requirements and the overall planning framework for Medicare contractor systems.
-
Detailed Instructions
Step-by-step instructions for completing the system security plan architecture materials and related worksheets.
-
Existing System Security Plans
Guidance on how existing plans fit into the overall architecture and how they relate to contractor security documentation.
-
High Level Diagram
Requirements for a summary diagram of system connectivity and external connections.
-
Additional Information
A list of supplemental HCFA and NIST resources referenced for further guidance.
-
Appendix A
Worksheet instructions covering the information requested for contractor control numbers, organizational details, system support, and related planning fields.
-
Appendix B
The SSP matrix reference section for general support systems and major applications, including update status fields and supporting explanatory material.
What You Will Learn
- How HCFA describes the security self-assessment process for Medicare contractors.
- What categories of system, personnel, and planning information are gathered for security documentation.
- How the system security plan architecture materials are organized at a high level.
- What supporting documents and references are identified for additional guidance.
Who Should Read This
- Medicare contractors
- Security officers
- Systems security staff
- Compliance staff
- IT operations teams
- Business partners preparing HCFA submissions
Subscribe or sign in to view the full article.


Quick, Current, Complete - www.findacode.com